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Abstract of J P831 5053 

PURPOSE: To provide a safe receipt-free betting 
system by using algorithm based upon number 
theory. 

CONSTITUTION: A bet generating center 10 
generates a betting choice to each better or each 
bet selecting means 12. Ciphering or shuffling is 
applied to a bet and the result of ciphering and 
shuffling is sent to the bet selecting means 12 
together with information on the method of 
applying shuffling to the bet without being 
intercepted on the way. The information is 
preferably transmitted through a safe tapping- 
disabled channel 16(i). Bet generation and 
shuffling verification using chameleon 
commitment and mutual communication proof 
can also be applied to this system. Thereby the 
betting system can be attained by using the 
tapping-disabled channel and a current personal 
computer provided with an access means to an 
electronic bulletin board. 
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12(1) fctfLTttftOMRKftg 

ffc-rs. tana, «s^ft*«tr;->^y 7U>^£;&S£ 
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4fV>^H6 (i) ^ilCTil^n*. 

<^fc. l!WfedE*«fctf s> 7 'J Aft 
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(2) 

1 

[»*JB1] (a) &&3att#&©fctt©&*&*l 
f8.LTn^m±.\Zt%m?Z>7>y-y 7-h. 

(b> &%t<tizz.ttL<&&mmmm\zmm*yt 

(c) %mmiR&BdfiW&*M!tlL *y±-i V*mfct 

7<h. 10 

[W*^2] ±E«ffl*y-fe--7£2tS7x<.y7(i. 
£fc«»atr*. »*3UfcE«©5fc£fcW->-h7 

[»*S4] ±ElEStt£iPJ§T£77<;/7tt, 1- 

o mm 7)vi u x a smfT-r s ^ t ic «t d ff ft^n* c 
tmmt-rz. w#«3KE«w>££&w>-h7u 

[w*«5] (f) ±fsag&*^-rsxx^yTfe 

h 'J > if* 3 5 v h? * Z. t ZStSZT- v 7£, 

(g) 35 v hantty bZm^Z>Z.t\z£K>ffii$ l 2 

(h) fflg*^tE&££&^>*;U£^LTx:3 3y 50 

« 3 tcE«©££& W->- h 7 U -ail # 3£. 
[»*9i6] ±.miE%&ZM.WtZXf-y7\$. 1- 

o HBjyjw^u XA^*ff r s - 1 ic<t off ^t>n-s c 

t^^mi-TS. If*15KE«©££&l/->-b7'J 

-an^. 

5 7 h^>h5»jjtnxfy ^»c^ty Jits 
o um 7 ;i/ =f u x a s^ff f * c; t <t d ff & fen s c 

££#®<!:-f-5. »#^7lcE«©£±ftl/->-h7U 
[fif^lO] ±12X7-5/ X (a) (i, 50 



&W¥8-3 15 0 5 3 

2 

(i) ±E»j«anfcisBSS->vy7;w-r5i:t, *± 

(i i) ±E">* y 7 'J >7*KMT5«ffl* yfe-S>ft, 
.Siesta fctwatr*. W*«ilclH«©^^p 

->-h7'j-a^sc. 

- h 7 U -MA^, 
[ftftHl 2] ±EXxy7* (a) tt, 
(i) ±E*J«3nfca»&5/Yy7^fS2:t. *«t 

(i i) ±e->* y 7 >j ytf\zm-z>$i-m* 
asanas t&<, ±Eft»a«*Rfca*cit*a 

->-h7U-a**s. 

[«M13] ±Etffl^7t-y^Xfyy 

■ **it&»»fra, »#3i4KE*©££fcU«>- 
h7U-a^*iCo 

[W*«14] ±EXt->>7 (a) tt, 

(i) ±E«j«snfcasft->*y7^-r*ct. 

(i i) iffiyf; 7 'J >^{cWrs*ffl^ y -fe-i 
#g£ns ±EanglR^g:l;:i£s;:<>:£$ 

im$miS] ±E»ffl^y-fe--7S3lS7T;-y7 
tt, JSK^oJtg^^^^^^S^bTjiSt)©-? 
$>Z>Zt*®®t?Z>, 1 4 tE«©5Sf^V-> 

-h7>j-as^. 

[if 1 6 ] ±EXf «y 7(a) \t, 

(i) ±E«SnfcjSI*yt f 7^1^:. i5«t 

(ii) ±EvY-y7'J>^CB8-r5*ffl^5/-fe-vS, 

^sans^<h^<, ±E»»aa^ftfca*c-isa 
&Kdo^t*»atr*. a*«7KE«©ss;**w 
v-h7U-as?*^. 

tt> JSK^nJ«6^^^ J V>^;U^bTji^'b©T 

-h7u-aa*^. 

t»*Wl 8] ±E7x-y7 (a) tt. 

(i) ±E«iaanfc»a&->*y7;p-r*ct. *«t 

(i i) igyfj 7 U >^fcMrs»ffi^ y-fe-S?*, 

^§an5r<i:^<. ±E»aa«^ata*nt&s 
t>\z-stszt*ftmt?z>. mxm3\zmm<D&-kti.i' 
->-h7'j-asi*ic. 
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(3) 

3 

[«*«19] ±E»ffl*y-fe-v£i£57>x>;/7° 
1 0 KE*©«£& 1/ h 7 «J -tftH* 

a. 

[W#«2 1] (f) #*M-> ■ 35>y b*>h£ 

(g) 35y han&tTy hftffl^*Ctt:±0±dll 
7*£, 

(h) &g3ti3;i£&<^n$y h-T-SX^-yT'tSr 

$ sc^trc ts^atra. m*m2 o fcE*©'*£ 

[Sf#^2 2] ±Ex35y hTSXxy^H, fflft 

^SC. 20 
[11*912 3] ±IBjEStt*EWrSXxy7*tt, SE 

v 7)V7)W) x&zmntz z. tcj; off 
n*c:t&w«frs, »*js2 o{ce«©££&i-> 

9H y 7)l7)l>3 U XA ftjdff "T -5 £ £ lc <k D frft* 

nacii^isi-ra. w*«2 ifcE«cD^^u-> 

[H^2 5] fs^V^y - a$7 M>b£«2Mt; 

1 CEft©&£& V'y- h 7 U -««2f5£. 

-r5Xx^7"^^e.»^tjri:^#m<h-r.5, «*«2 
3 fcE*©5fc£fc 1/ h 7 U -SH^jL 

Mt4Xfy 7°ti, ±E v ^ y 7 U ©&»©»« 
«£±E»*fiK4A«ci«£«i;ifcfttt«i-r*, 
M&H 2 6 fcE«©££fc US/- h 7 'J 
[IT&JI2 8] m&<D&m£.!&t>i>-t. . 

SHBMHr 

±ES»£jfrfe>*-tt, ±Ef9:JS#©£*©£«>©i9: 
lg£«J&LT±Eif*«±f;:Jf^U Sfcfc, ±ES* 

±Eja*a«?^a©ft*tt. t 



#M¥8-3 1 5 0 5 3 

4 

E«©££fc U h 7 U -fi^gflo 

hU 35 y hStlfc ty h*ffllr»TS*«|jfc©IEi!§tt 
5y hi-*X^y7 s £3£»CfTfc5£££&&£T5, 

mim 2 8 fcE*©*±& u v- h 7 u -sjrsii. 
m*m 3 1 ] -hEftnaiR^att. w-> • 3 

5-7 h^>KS:*im-rSX5 1 2/7"*$e.t'ff^0^i: 
5r^lSfr-5, 3 0 (CE«©^^U->- h 7 <J 

[M$£3 2] ±E*WSSn&SJK*»#i*fc»© 
A, 

±Eyt7 7Wi; M*J©#i"*".y7U>iMz>*- 
2 8 fcE*©££fc U v- h- 7 'j -8HgH. 

^±E^siR?aiciiact^#afr-5, »*«3 

2 ke«©$£&u h 7 U -&H&B„ 

[»*«3 4] ±E»S3n&J8«*S»tfc*fc»© 
->^^7U>^-fe>^-©->^>y7;P^yh*$e.{CM 
A, 

±E->.^ v 7)V*-y hrt©#->ir s> 7 U >^-fe>^- 

5, »**3 0tE*©5R*&U->-h7U-ft»S 
[i*S3 5] ^v^^7'J>y-b>^-«. Stt^: 

4 ICE«©*^ U->- h 7 'J -S^ggo 
CBI*a3 6] ±E->Y>y7'J>^-fe>^-tt, 
K, »*««©IEatt*Ki»f4X7-y^*Rft5J:i: 
«r#afr^>. W*«3 2{CE*©*^Uv'-h7 l J 
-SUSS, 

[»*«37] #->^«77U>^-fe>^-tt, 

• 35y h^>h*ffl^T7>^AXh'J>^£3 

5-^hb. 35 h$nfct<y b&m^T&mmfiwiE 
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(4) 

5 

Witt*. **JB3 7fcB*©*f£fcl'5'-h7'JHtt 
[M&H3 9] «»»a^s^. **m-> • 3 5 

(i*J|4 0] ftttl«¥S». tOStttlG 
*s * y 7 >J > ^-fe - \z i & »±BJS*« K 4 A 2> H 

R*a3 9KElt<Dft£ttW'--h7U 10 

[£91©Bin&Kn] 
[000 1] 

[5Ba©«-r*ft*»»] *«att, ££&Wv-h7 
U-«*S*fcWffl&#5&fc<fctf8ai::HU fcfc, £ 
£fc 7 U-tff aftaC*^ 

[0 0 0 2] 

[&*©&«] ££fc«?-ifta©«»a£fc, ttatt& 

[0 0 0 3] SiETK, STOC94 (1 9 9 4f5E 
ff) ©5 4 4-5 5 3MfC««Snfc fRec e i p t 
-free Secret-ballot Elect 

ion (w s/- h 7 y -i&fgsaa*) J t «•* J . 

C. Bena 1 oh^wifcfcfc, feS«&ll7a brut- 

[0004] Benalo a:fe<J;t*Tu 1 n s t r a 
tt. ^l©V->-h7U-«^SM7'nh3;U&ffi^L 

a#a* r»/£/s*fj •c**cfco7*;p-7*ttJ6t& 

0, TO/JtJ&l T**Ei©:/>-7fttt»L&»J 
t*Cti(*T*S. ;r©<fc5&7>-7«, 31 

[0 0 0 5] untttffJK, Ni eml^WRenv 
a 1 UJ, A S I A C R Y P T ' 9 4 ( 1 9 9 4 ¥5E 50 



ftM¥8-3 1 5 0 5 3 

0 

ff) ©14 1~14 8H(C^«$nfe THow to 
prevent buying of votes i 
n computer elections (a>t!a 
v»T»»©Ktt*BOSFiS) j iBTSN 
i em i 6©HXfc*V»T, £©IIIB**ftUJ:5£l, 

[0 0 0 6] 

[RW^ftUAifr-BUM] Benaloh-Tu 

1 n s t r a*5<fct*N iemi-Renval 1 ©7'D 

»MMt^fcotimoT^5. «£&*«?»© 
nisii, ft^&i/s/-h7U-ass»jjw*fc*ttt 

[0 0 0 7] 

[0 0 0 8] *»WlCJ:*J(f434^-h7UHSBWr 

a»©K»ftas&v». raa^a&R^^^>* 

£©£3&a**pia&?ir>*;M4» 1 9 92f 10 
fl^ffCDScientif ic American,^ 

2 6 7itg4f, 5 0~5 7ICj|i$nfc TQuan 
turn Cryptography (S^Bf^fe) J £ 

a-rsc. Benne 1 t ^©i&xcgaasnT^*. 
rttiifisn^^t-; ^©7>-7£^Bjfiirr£. 

£Hu aa«n9attt*Wr*J:D«lC^yfe-5?©rt* 

**afcav»6n*7*n Hajvcko, i»tjfc^©ai 
fc*»©«ftttuaTttftv». m>&*n«. is«g^pi«g 
a: < ^ y -t — 7&ears ^ t s ^ 5 . 

[0 0 0 9] «T©liiW(cfev>T, r*/^^>.ns 
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(5) 

7 

35 5/*-*t35y hbfct*50x35 y - 

[ooio] *»«©#5tfc.fcfttt, aa£ft-fe>*- 

<k, ajMMHs^^-t, «*©-fe>*-£aaa#4: 
[0 0 11] SlOXfy^tt, 

ftasMSfc^LT. £>£&©& £^5^tgfcaa£fgfT 
a»2mi, -r*fc%> ru mt roj ST^stig 
>?A£S»u©Hr*HtSft;fc r i j at roj 

5. 35y^-tlWW> • h • 35y h*>r- 
Sffl^TE5«Jfc»UT3 5y hf*. 35 

aa#©*tcE?iJ£x3 5 v hTS. 
[0 0 12] »2CXfy^i. aa±ftfe>*-a>S 

7**y hft^bTfi3R#i t*fr*2"3©»3!lS->ir 
y7)VtZ. 35y*-tt, 35y M> 

T35yr*f*. &yt77U>yt>^-lt *©» 
.fls©IE3tt£B9rr*. 3 5«^^-li» KfflnWR&ft 50 

[0 0 13] SfS2©Xx<;/:/tt!&$I©t>©Ttt&<, =f 

irrsssctt, a»t*-fe>^-tt. a*©?*;'* 
***LTaa#fcaa, am^si*.. 

[0 0 14] »3©X7 i y^tta»*fc±ftE*15ai"P 
*4. «3R>t*©S«]©BB5iJ«St, ^2©Xxy7 r (C* 

*<££»C«fcl5. #aa#Ktt£%&©a**£ftT*S 

ftaa^riswufcasoa-feoio*. 40 
«. -3^, *ffl-fe>^-»asua:*fHfr5. 

[0 0 15] >*JWE>*flHU 19 9 3 

^SEff © A d varices inCryptolog 
y, Eurocrypt '93©248~259H 
tCJliScStlfc TEfficient Anonymou 
s Channel andAl 1/Nothing 
Election Scheme GjWW&K^A' > 

*7 • i-y*>ifisaus&> j tm 

-T*C. Pa r k6©aiX^>, #«Wtn-©««AlC 50 



ftgfl¥8-3 1 5 0 5 3 

8 

Sligc?lafc TS e c u r e Anonymous Me 
ssage Transfer and Voting 
Scheme yte-S>«a*J:tf»* 
J iB*5*H»«WtiBS60 8/3 7 6, 5 6 8 

vcasn-o**. *»9jfcJ:ntf. #»©t> 
- 7 ft* - 7>- 7 \z&tfi? s z. t \z «k o t>- 7 Off 

[0 0 16] 

TPIBIfcKg]*-*. 
[0 0 17] #BiJB©ff*U»£li©»»K.fc**£fc 

*»9J©#5$KJ:n«. JSM)£yptX2 6 

»c<t oaa^ft-fc^*- 1 o *tftftL&«f^ba*tt. 
a^a^ai 3-?-©te©^*7^-txRitg/ft^»^sji 
Kaf*an*. is^tastt. &aaa#;^g!i2 

(i) tc*fLT, y yy&timmzM^&fift rij n 
<t roj a©*r*^fc-2>. ^^caS4ft-fe>^-i o 
a. aas^¥©i2 (i) \zm-**mc&mifie0 

6 (i) s^ut, aaa#:^ai2 (i) ic^ice 
its. mmiz. aa£ft-fe>*-i oa. aatai, 
tk, a»36*»jEKfeftanfcc:tft, arattf&ic 

*. Cft6©Ki»tt. «5fi-r5«fc5fc. *©K9!7*n-fe 

^2otj:o*ffsna. 

[0018] aaaK^ai 2 (i> «, imu&ickk 
5ina«M i ir>*;n 6 (i) ft^uTaa*ft-t>^ 

«r-t«. aaaa^ai 2 (d . 12 (2) . 
12 (i) ict oaa a n^aaa. aa*ihfe>*- 

ns„ ^&i«ft>#i4ii 5+^>^>^ 

-14 (1) , 14 (2) , ■«, 14 (n) IZ&Vnm, 

tj:o*-*ic»asn, s^Mt>^-i 5^ ^> 
^Ac*ojiBi!^iiicEMbfc-ffl©*i«^baattt 
jHg*t*m*-r**TttW6n*. aa*ft-t>^- 
io. aas^?ai2 (i> , 5^-»^-t>^-i 
4 (i> , aaasf-fe>^-i 5©&4«» m-s^a, 

[0 0 19] *5698©*5jC©*a&tt[flU&*». 
^IC. aa«ft^3"tX2 6t, tEBJ^n-feT.2 0 

n*i«i©B«ct)i»TRi«-r*. 
[0020] aa*ft-b>^-i o\t. aa«ftyD-b 
x 2 6 suff -r?) ^ ti:± 0, #aasj?#a 1 2 
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(6) 
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10 



(i) tc&LT roj m&kzt r l j |(*&fr5*HHb 
ffl^T. &&I!ljIft#a 1 2 (i) 

[0021] ru jut roj mommt^m\t. 

vi 0 = (g r 11 mod p, 
vi 1 = (g' l! mod p, 
^Tri , fcitf r , 2 ttSHS^^S 1 2 ( i ) fc 
#*Mb»£aftT*0, p, g, y, mo , mi 

SL»ri i fcitfn 2 £ffl^T±5$£f|-g-f Sits 

[0 0 2 3] «3K£jS-fe>*-l Ott. 2#©ltf>?|i$ 
T (vi 0 , v, 1 ) OffltC, -tnafltt (v, 1 , v 

. 0 ) ©rate, »sMR±c«wr*. 

[0 0 24] rayn-fcX2 0«, 3-3>©7>>U3*UXA 

A21. 1 -0t£BJ7JP3*'JXA2 2. x3IS? 
b7Jl'3*iJXA2 3Tfc-5. 33? M>h7;U3*»JX 
A2 1I1 ±EEWK:'3V»T©*>l/*>'35?h^ 
>hi, o^fcoi -0IEBJXnha;ncffl^e.n57> 

M > h 7;W J XA 2 3 tt, S«WF UIB* 
>*;Hfctfl/T» 35? M>h7;i/3PJXA2 IK* 
HT3 5«( hZntctitl'ty • 357 M>b£x3 

5? htsfcfetfflt^ns. l-osn&ktto^i' 

:*> • as? M>h/x35? M > b©7^3*UX 

Afco^tte&ji-r*. 

[0 0 2 5] fiH&frfe^-tt, *^l^t>-T3S 
?M>hT**, f35y^-©(l)^S; ( 
ft^*>*^*^LT!l8R»R*«l 2 (i) 

[0 0 2 6] SSHSiR^ai 2 (i) fct fcEXn-feX 
2 4C£D. l-OKWT^UXAOiESttt, t3 
3? M>h©*»ttfc*itr*. cn&OIEiSttfc* 
»tt*UMiE3ft*i. aigjIiR^a 1 2 (i) », 
Xn-feT.2 5**frU »SMR±o«H»fl:JS»o5%, $8 
Eo (v° ) = (g' ' mod 
Ei (v 1 ) = (g r " mod 
* LT. 31 5 ? h Stl&X h 'J Ltclfi-D ttKUfC 
Eo (v° ) SitfEi (V ) Sji^-rS. 

[0 0 3 3] 2a. l/2©«$$fcoT> BEBJ^a 
«. r ' *J:tfr" *W6*>K-r*Jlt«K*sn6. 
&SE^aWU Eo (v° ) feilXEi (v> ) *t?Jff 

[0 0 3 4] 2b. l/2©W*t)t>T, BEBJ^a 



(UMBO 8/3 7 6, 5 6 8*KB«Snfc36rtS*J:lJt 

SBfcJBK rij ro j *©iWfc»lBfcotf© 

[0 0 2 2] 

mo • y ' 11 mo d p) 
mi • y ' iJ mo d p) (1) 
**©*JlS*&to-J-l^*MR-r*. &SSMiR#at£ 
ifl tt» flHJfl:iSBR38«£©J:5ftEWC***>3&«*^U*> 
• t3S«; h^>h3&»6to*»*©Tf, lELHSflS't* 

[0027] ®mmft^®i2 (i) tzj;D«Rsn& 
sura, tt©tt»a*?*aKj:o«Rsnfctt©ijwt 

[0028] ±jfi©#ftftaj8T*fc. KKfc&#flt& 

^S«^ai2 (i) (C«©SX«H«-r«i:2:ft3Mf 

a? 16 (i) 4«KKsna:v»»fro. a&stt&antf 
r 1 j Ita&ofc* ro j MTfcofcfr©ft#«ft7> 

[0 0 2 9] o€fJC, l-0K9ifc&tffc*;<M->« 
35? M>h/x35? h^>h©7^3f'JXA?£ia 

wr*. i-ogEW7;u3fuXAtt, mw^wtt&m^ 

5ttET<bJ:V». JI©7Jl/=PJXA©»**»tt. m%tt 

Ay3/aH*©Hi*icj:Dtfcfisn*«», ?>y& M— 

30 3>T?"b«fcH. 

[0 0 3 0] d©7;VrfiJXAtt. i£ (1) CLfc*t 0 
T4*4n«wStifc. ?>^Afcat"C*Afc» (vi 

0 , vi-») *gttr> -ene.*tnis(c ru «?t 

roj *©»T*«tttWf*Ctt^T»V»*. 
TT. ttJKHR¥ftC#l/r. • 35? M> 

©tffijgf*. 

[0 0 3 1] 1 -OBE^icf'JXA 

1. BEBJ#a«r' . r" ft-«fcWRU ^©tfff^ 

[0 0 3 2] 

p, mo -y' ' mod p) 
P, mi - y'" mod p) 
fi. si = r 1 1 - r ' *5<ktXs ! =ri ! - r* SI 

&*>tc-r^ct«:s*$n2>. ^E?a«. s • . 

S2, g, ySJBHTEo (v°)*3<t^Ei (v 1 ) 
?^T-5. 

[0 0 3 5] • 315? h^>hS«£BJ 

50 wr*. *>n^*>'35yh/>Htttt, am«t« 
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[0 0 3 6] X>t^<DMv br&zozituiz 

[0 0 3 7] 35^ M>h : iHtaSBtt. S®8C(C^ 
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L Title of Invention 

Secure Receipt-iVee Electronic Voting 

% Claims 

1. A method of secure receipt-free voting comprising the steps of: 

(a) constructing votes for each vote chooser which votes are posted 
on a bulletin board; 

(b) sending private messages to respective vote choosers without 
being intercepted; 

(c) the vote chooser choosing the vote and constructing a message; 

(d) the message from the vote chooser reaching a vote counting 
center through a secure anonymous channel; and 

(e) the vote counting center counting the votes. 

2. A method of secure receipt-free voting as set forth in claim 1, where said 
sending private messages comprises sending via secure untappable channels. 

3. A method of secure receipt-free voting as set forth in claim 1, further com- 
prising the step of proving the correctness of the vote construction. 

4. A method of secure receipt-free voting as set forth in claim 3, where proving 
the correctness is performed by executing algorithm prove 1-0. 

5. A method of secure receipt-free voting as set forth in claim 3, further com- 
prising tie steps of: 

(f) said constructing votes including committing a random string 
using chameleon commitments; 

(g) proving the correctness of the constructed votes by using com- 
mitted bits; and 
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(h) decommiting through a secure untappable channel. 

6. A method of secure receipt-free voting as set forth in claim 5, where proving 
the correctness is performed by executing the algorithm prove 1-0. 

7. A method of secure receipt-free voting as set forth in claim 5, further com- 
prising the vote chooser invalidating chameleon commitment. 

8. A method of secure receipt- free voting as set forth in claim 7, where proving 
the correctness is performed by executing the algorithm prove 1-0. 

9. A method of secure receipt-free voting as set forth in claim 7, where the 
vote chooser invalidating chameleon commitment provides its secret key for 
constructing votes to the bulletin board. 

10. A method of secure receipt-free voting as set forth in claim 1, where step 
(a) further comprises: 

(i) shuffling the constructed votes; and 

(ii) sending a private message about the shuffling to the vote 
chooser without being intercepted. 

11. A method of secure receipt-free voting as set forth in claim 10, where said 
sending a private message comprises sending via a secure untappable chan- 
nel. 

12. A method of secure receipt-free voting as set forth in claim 2, where step 
(a) further comprises: 

(i) shuffling the constructed votes; and 

(ii) sending a private message about the shuffling to the vote 
chooser without being intercepted. 

13. A method of secure receipt-free voting as set forth in claim 4, where said 
sending a private message comprises sending via a secure untappable chan- 
nel. 
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14. A method of secure receipt-free voting as set forth in claim 5, where step 
(a) farther comprises: 

(i) shuffling the constructed votes; and 

(ii) sending a private message about the shuffling to the vote 
chooser without being intercepted. 

15. A method of secure receipt-free voting as set forth in claim 14, where said 
sending a private message comprises sending via a secure untappable chan- 
nel. 

16. A method of secure receipt-free voting as set forth in claim 7, where step 
(a) further comprises: 

(i) shuffling the constructed votes; and 

(ii) sending a private message about the shuffling to the vote 
chooser without being intercepted. 

17. A method of secure receipt-free voting as set forth in claim 16, where said 
sending a private message comprises sending via a secure untappable chan- 
nel. 

18. A method of secure receipt-free voting as set forth in claim* 3, where step 
(a) further comprises: 

(i) shuffling the constructed votes; and^ 

(ii) sending a private message about the shuffling to the vote 
chooser without being intercepted. . "'. 

19. A method of secure receipt-free voting as set forth in claim 18, where said 
sending a private message comprises sending via a secure untappable chan- 
nel. 

20. A method of secure receipt-free voting as set forth in claim 10, further 
comprising the step of proving the correctness of the shuffled constructed 
votes. 
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21. A method of secuie receipt-free voting as set forth in claim 20, further 
comprising the steps of: 

(f ) committing a random string using chameleon commitments; 

(g) proving the correctness of the shuffled constructed votes using 
committed bits; and 

(h) decommiting without being intercepted. 

22. A method of secure receipt-free voting as set forth in claim 2L where said 
decommiting is through a secure untappable channel. 

23. A method of secure receipt-free voting as set forth in claim 20, where said 
proving the correctness is performed by executing the algorithm prove shuf- 
fle. 

24. A method of secure receipt-free voting as set forth in claim 21, where said 
proving the correctness is performed by executing the algorithm prove shuf- 
fle. 

25. A method of secure receipt-free voting as set forth in claim 21, further 
comprising invalidating the chameleon commitment. 

26. A method of secure receipt-free voting as set forth in claim 23, further 
comprising invalidating the chameleon commitment. 

27. A method of secure receipt-free voting as set forth in claim 26, where the 
said invalidating chameleon commitment includes providing a secret key for 
said shuffling to the bulletin board. 

28. An apparatus for secure receiptee voting comprising: 

a plurality of vote generating centers; 

a plurality of vote choosers; 

a bulletin board; 

a vote counting center; . 
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said vote generating centers constructing votes for each said vote 
chooser which votes are posted on said bulletin board and said 
vote generating centers sending private messages to respective 
vote choosers without being intercepted; 

each said vote chooser choosing the vote and constructing a mes- 
sage which reaches said vote counting center through a secure 
anonymous channel; and 

said vote counting center counting the votes. 

29. An apparatus for secure receipt-free voting as set forth in claim 28, where 
said vote generating centers send private messages to said vote choosers via 
secure untappable channels. 

30. An apparatus for secure receipt-free voting as set forth in claim 28, further 
comprising: 

said vote generating center committing a random string using 
chameleon commitment; proving the correctness of the vote 
construction using committed bits; and decommiting through 
a secure untappable channel. 

31. An apparatus for secure receipt-free voting as set forth in claim 30, further 
comprising said vote chooser invalidating the chameleon commitment. 

32. An apparatus for secure receipt-free voting as set forth in claim 28, further 
comprising: 

a shuffle net of shuffling centers for receiving said constructed 
votes; and 

each shuffling center in the shuffle net shuffling the votes and send- 
ing a private message to a vote chooser without being inter- 
cepted. 

33. An apparatus for secure receipt-free voting as set forth in claim 32, where 
each shuffling center sends a private message to a vote chooser via a secure 
untappable channel. 
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34. An apparatus for secure receipt-free voting as set forth in claim 30, further 
comprising: 

a shuffle net of shuffling centers for receiving said constructed 
votes; and 

each shuffling center in the shuffle net shuffling the votes and send- 
ing a private message to a vote chooser without being inter- 
cepted, 

35. An apparatus for secure receipt-free voting as set forth in claim 34, where 
each shuffling center sends a private message to a vote chooser via a secure 
untappable channel. 

36. An apparatus for secure receipt-free voting as set forth in claim 32, fur- 
ther comprising said shuffling centers proving the correctness of their vote 
construction. 

37. An apparatus for secure receipt-free voting as set forth in claim 36, further 
comprising: 

each shuffling center committing a random string using chameleon 
commitment and proving the correctness of its vote using com- 
mitted bits, and decommiting without being intercepted. 

38. An apparatus for secure receipt-free voting as set forth in claim 37 where 
said decommiting is through a secure untappable channel. 

39. An apparatus for secure receipt-free voting as set forth in claim 37, further 
comprising each vote chooser invalidating the chameleon commitment. 

40. An apparatus for secure receipt-free voting as set forth in claim 39, where 
each vote chooser invalidating the chameleon commitment by providing its 
secret key to said shuffling centers or to said bulletin board. 
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3, Detailed Description of Invention- 
Field of Invention 

The present invention relates to a method and apparatus useful for secure receipt- 
free electronic voting and specifically, to number-theoretic based algorithms for 
secure receipt-free electronic voting. 



Background of the Invention 

The. ultimate goal of secure electronic voting is to replace physical voting booths. 
Achieving this goal requires work both on improving the efficiency of current pro- 
tocols and understanding the security properties that these physical devices can 
provide. 

Recently,: it is observed in an article by J.C. Benaloh et al, entitled "Receipt- 
free Secret-ballot Election/ 1 in STOC 94, pp. 544-553 (1994), that unlike physical 
voting protocols, nearly all electronic voting protocols give the voters a receipt by 
which they can prove how they voted. Such receipts provide a ready means by 
which voters can sell their votes or by which another party can coerce a voter to 
vote in a certain way. 

Benaloh and Ttiinstra give the first receipt-free protocol for electronic voting. 
In their scheme a trusted center generates for each voter a pair of ballots con- 
sisting of a "yes" vote and a "no" vote in random order. Using a trusted beacon 
and a physical voting booth the center proves to the public that the ballot indeed 
includes a well-formed (yes/no) or (no/yes) pair and at the same time proves to 
the verifier which pair it is. The physical apparatus ensures that by the time the 
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verifier is able to communicate with an outsider, the verifier can forge a proof that 
the ballot is (yes/no) and also forge a proof that it is (no/yes). Thus, such a proof 
ceases to provide either proof as a receipt. 

Independently, Niemi and Renvall tried to solve this problem in an article by 
Niemi et al, entitled "How to prevent buying of votes in computer elections" in 
ASIACRYPT '94, pp. 141-148 (1994). They also use a physical voting booth 
where a voter performs multiparty computation with all the centers. 

Both the Benaloh-Tuinstra and the Niemi- Renvall protocols illustrate that receipt- 
free secure voting is possible. However, their physical requirements are fairly cum- 
bersome, and are not unlike those faced by participants in physical elections. An 
important open question is precisely what physical requirements are necessary for 
achieving receiptee secure voting. 

In accordance with the teachings of the present invention, a secure receipt-free 
voting scheme is described with a more practical physical requirement, that is the 
existence of a physically secure untappable private channel. 

Summary of the Invention 

A secure receipt-free voting scheme is described where each voter does not leave 
evidence of how the voter voted by using a physically secure untappable channel. 
The term "untappable secure channel" refers to the fact that a message can be 
sent from a center without being accessed or detected by another party. Such an 
untappable channel is described in an article by C. Bennett et al entitled "Quan- 
tum Cryptography" in Scientific American, vol. 267, no. 4, Oct. 1992, pp. 50 to 
57. The end result of using an untappable channel is that neither the voter nor 
another party can show or prove how a vote was cast or what was the message 
that was sent. Once a message is sent or received, the content may be changed 
rendering proof of the message impossible. However, if the message is intercepted 
or detected in route or at the time of reception, the intercepting or detecting party 
can learn the content of a message prior to a time when a change was possible. 
Moreover, even if a non-secure channel is used, if the message travels along the 
channel without interruption or detection, by virtue of the protocol used in the 
present invention, determination of a particular vote after receipt at its destination 
is not possible. In other words, an untappable channel refers to the transmission 
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of a message without interception or detection in route. 

In the following description, the term 'chameleon commitments 1 is used. A chameleon 
commitment is a message committing and decommiting protocol, where the com- 
mitter can decommit as the committer committed, while the receiver can decom- 
mit in any way, regardless of how the committer committed. 

In accordance with the method of the present invention, there is a vote gener- 
ating center, a vote counting center, and shuffling centers to transfer messages 
between the various centers and each voter. The method comprises the following 
three steps. 

The first step is the generation by a voter generating center of a set of all possible 
votes for each voter. For simplicity, it will be assumed that the possible votes are 
two, namely 1-vote and 0-vote. For each voter t, the vote generating center posts 
encrypted 1-votes and 0-votes in random order. The committer commits to the 
ordering using chameleon bit commitments. The center proves that the committer 
constructed the vote-pairs prdperly. The committer decommits the ordering only 
to the voter through an untappable secure channel. 

The second step is the transferring the vote from the vote generating center to 
the voter via the shuffling centers. Each shuffling center shuffles the two votes 
for voter i through a shuffle-net. The committer commits with regard to how the 
votes are shuffled using chameleon commitments. Each shuffling center proves the 
correctness of its action. The committer reveals how the votes ware shuffled only 
to the voter i through an untappable secure channel. 

The second step is not mandatory, in which case the vote generating center may 
directly send the vote to the voter through an ordinary channel. 

The third step is anonymous voting by the voter. By keeping track of the initial 
ordering of the pair, and how they were shuffled during the second step, each voter 
knows which vote is which. Each voter submits one of the received votes to the 
counting center through a secure anonymous channel. Then the counting center 
tallies the votes. 

Implementation of a secure anonymous channel can be found in an article by 
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C. Park et al entitled "Efficient Anonymous Channel and All/Nothing Election 
Scheme" in Advances in Cryptology, Eurocrypt '93, 1993, pp. . 248 to 259, or 
in pending U.S. patent application serial number 08/376,568 entitled "Secure 
Anonymous Message Transfer and Voting Scheme" which is assigned to the same 
assignees as the present invention. Also, the invention results in a method which 
reduces the amount of communication and computation necessary to generate, 
transmit and check the proofs by combining multiple proofs into a single proof. 

The present invention will be best understood when the following description 
is read in conjunction with the accompanying drawing. 

Detailed Description of the Invention 

A preferred embodiment of a secure receipt-free voting scheme comprising the 
present invention will now be described with reference to. Figures 1 and 2. In 
accordance with the scheme, the encrypted votes generated by vote generating 
center 10 by vote construct process 26 are posted on an electronic bulletin board 
13 or other publicly accessible messaging means. The encrypted votes are pairs 
of 1-votes and Q-votes, permuted in random order, for each vote chooser 12(i). 
Then the vote generating center 10 secretly conveys to the vote chooser 12 (i) 
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through an untappable channel 16(i) how the encrypted votes for vote chooser 
12(i) is ordered. At the same time, the vote generating center 10 needs to prove 
to the public that the vote was honestly generated and to the vote chooser that 
the center 10 had not sent false information in the secret message. These proofs 
are achieved by following prove process 20 as will be described below. 

The vote chooser 12(i) chooses its ballot using the secret message from the vote 
generating center 10 through a physically untappable channel 16(i). The vote 
chosen by the vote choosers 12(1), 12(2), ...12(£) are transferred anonymously 
through a secure anonymous channel to a vote counting center 15. The secure 
anonymous channel can be realized by the mixing centers 14(1), 14(2), . . .14(n), 
where encrypted votes are successively processed by the mixing centers until the 
vote counting center 15 provides as its output a randomly, untraceably ordered set 
of unencrypted votes and the outcome of the tally. Each vote generating center 
10, vote chooser 12(i), mixing center 14(i) and vote counting center 15 comprises 
a computing means, preferably a personal computer but it may also be a work- 
station or the like. 

Having set forth an overview of the scheme, the detail of vote construct pro- 
cess 26, prove process 20, and the information being transferred securely through 
untappable channel 16 will now be described. 

The vote generating center 10, by executing vote construct process 26, generates 
an encrypted pair of O-vote and 1-vote for each vote chooser 12(i). The center 
follows the vote construct process for each vote chooser 12 (i) with independently 
chosen random numbers. 

The encrypted form of 1-votes and 0-votes need to be appropriate for input to 
the anonymous channel. Preferably, the method and apparatus described in U.S. 
patent application 08/376,568 which is incorporated herein by reference, is used 
and the encrypted forms of 1-votes and 0-votes are selected to be: 

V? = (g T u mod p, m Q • y T n mod p) 

*V = (g T i2 m od p s m l • y T i2 mod p) (1) 

for independent random numbers r« and r a for vote chooser 12(i) and appro- 
priately chosen common constants p,g,y,mo and mi for all vote choosers. The 
vote construct process 26 comprises calculating the above formulas with randomly 
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chosen numbers ra and r i2 . 

The vote generating center 10 posts on the bulletin board in the order of (v?,ti/) 
with probability of one half and (v? , v?) otherwise. 

The prove process 20 comprises three algorithms: commitment 21, prove 1-0 22, 
and decommitment 23. The algorithm commitment 21 is used to calculate and 
post a chameleon commitment of the above ordering and a random sequence used 
in the succeeding prove 1-0 protocol. The algorithm prove 1-0 is executed multiple 
times to prove that the center 10 generated the votes honestly, and the output 
is posted on bulletin board 13. The algorithm decommit 23 is used to decom- 
mit the chameleon commitment committed in algorithm commit 21, through an 
untappable secure channel. The specific algorithms of prove 1-0 and chameleon 
commitment/decommitment will be described below. 

The vote generating center sends an output of a decommitter, which is a chameleon 
decommitment, to the vote chooser i through the untappable channel. 

The vote chooser 12(i) verifies the correctness of the prove 1-0 algorithm and 
the validity of decommitments by verification process 24. If the correctness and 
validity are verified, the vote chooser 12(t) follows selection process 25 and chooses 
either one of the encrypted votes on the bulletin board, which expresses its opin- 
ion. The vote chooser is able to choose correctly because it would know how the 
encrypted votes were ordered from the chameleon decommitment. 

The vote chosen by the vote chooser 12 (t) will be input to a shufflesnet, together 
with other votes chosen by the other vote choosers; 

Applying the scheme described above, a malicious party who coerces the vote 
chooser 12 (i) to disclose its vote, will not receive a concrete proof of whether the 
chosen vote was a 1-vote ora 0-vote unless the vote generating center 10 is allowed 
to disclose the vote or the secure channel 16(i) is tapped into. 

The algorithms prove 1-0 and chameleon commitment/decommitment will now 
be described. The prove 1-0 algorithm involves a prover and a verifier. The 
prover is the vote generating center in this case. The verifier may be any entity, 
including vote choosers. The probabilistic behavior of the algorithm will be de- 
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termined by an output of a suitable hash function, but it may also be a random 
beacon. 

The algorithm comprises, given randomly permuted pair of •) generated and 
posted as equations (1), showing that they are indeed a pair of 1-vote and D-vote. 
Assume a random string has been committed using chameleon commitment to the 
vote chooser. 

prove 1-0 

1 The prover uniformly chooses r*, r" and calculates 

E 0 (V°) - (gr' mod Pj iuq - y r ' m od p) 
E^V 1 ) = (g*" m od p 3 m, • y r "mod p) 

and posts Eq(v°),Ei[v 1 ) in the order according to the committed string. 

2a. With probability 5, the prover is asked to reveal r $ and r". The verifier 
chedcs if Eo(v°) f E\ (v 1 ) is made consistently. 

2b. With probability the prover is asked to reveal si = — r* and s2 = 
r % 2 — t'\ The verifier checks that vf and vj can be indeed generated from 
Bo(v 0 ) y Ei{v l ) using $1,32,$ and y. 



The chameleon commitment scheme will now be described. The chameleon com- 
mitment scheme involves a sender and a receiver. The sender is the vote generating 
center in this case. The receiver are the vote choosers. 

The following is explained in terms of committing a single bit, 0 or 1, but can 
be easily transformed to commit multiple bits and strings. In the scheme, the 
receiver is assumed to know a satisfying a = g° for public integer a. 

Commitment Sender commits 0 by g r and a • g T for 1 to the receiver. 

Decommitment Sender reveals r. The receiver calculates both g T and a-tf and 
determines what was the committed bit. 
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In order to modify the decommitment, the receiver may claim it received r - a 
instead of r, which is the case when the sender committed the other value. 

A more detailed description of chameleon commitments can be found in article 
"Minimum Disclosure Proofs of Knowledge" by Brassard, Chaum and Crepeau in 
JCSS, pages 156-189, 1988. 

After the vote generating center decommitted its random string, the vote chooser 
12(i) may follow with invalidation process 27 to invalidate the commitment of the 
center. The invalidation process 27 comprises informing the center of the value a, 
so that the center also has the ability to provide false information afterwards, or 
to post the value a on a bulletin board 13. 

lb make sure that the vote chooser has the ability to modify the commitments, 
that is, the vote chooser knows the exponent o, the interaction may occur be- 
tween the vote generating center and each vote chooser, before the commitment 
is applied, or even before the start of voting. For example, the vote choosers may 
execute a cut-and-choose protocol to pick the constant a so that the vote chooser 
knows a with high probability. 

In order to make the receipt-free property more secure, it is possible to incorpo- 
rate a shuffle net 11 comprising multiple shuffling centers 11(1), 11(2),. . .ll(m) t 
as shown in Figures 3 and 4. Each encrypted vote generated by vote generating 
center 10 for vote chooser 12(i) is passed through shuffle net 11 before reaching 
the vote chooser 12(i). As a result of so doing, a malicious party would not be 
able to determine how the vote chooser 12(t) voted unless it colluded with all 
the shuffling centers and vote generating centers, or wiretapped every secret chan- 
nel 17(1), 17(2), . . .17(m) between the shuffling centers and the vote chooser 12(i). 

Each vote shuffling center comprises a computing means, preferably a personal 
computer but it may also be a workstation or the like. 

The operation of the shuffle net and shuffling, centers will now be described. Shuf- 
fling center processes each message posted by the previous shuffling center 
U(j - 1) (or the vote generating center 10, when j = 1) and posts the results of 
process shuffle 30 (Figure 5) in permuted order until the last shuffling center ll(rn) 
posts the result of the shuffling. Each shuffling center conveys how the votes were 
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shuffled to the vote chooser through an untappable secure channel 17(j). Each 
shuffling center proves it shuffled honestly and did not provide false information to 
the vote chooser in a manner similar to that of the vote generating center, -which 
is achieved through executing process prove 31. 

Figure 5 illustrates the operation of a shuffling center ll(i). The shuffling center 
ll(i) executes the processes shuffle 30 and prove 31 and posts the outputs. The 
process prove 31 comprises an algorithm commitment 32 which chameleon com- 
mits the random . string to the vote chooser. 

The process prove 31 further comprises three algorithms: commitment 32, prove 
shuffle 33, and decommitment 34. 

In order to describe the process shuffle 30, let the input be encrypted shuffled 
votes, which are presented as: 

*i = (A lt A 2 ) 
Xi = (fl lf B a ) 

The algorithm shuffle comprises generating a random number c\ and c 2 and shuf- 
fling the encrypted votes X\ and X 2 as 

S(X X ) = (A x • gt\ mod p 3 A 2 • y c \ mod P) 

S(X 2 ) = (B l • gc 2 mod Pj £ 2 . y c 2 mod p ) (2) 

and posting S(X\) and S(X 7 ) in random order. 

This order and a random sequence to be used in the algorithm prove shuffle is 
committed using chameleon commitment and posted on the bulletin board as the 
output of algorithm commitment 32. 

The algorithm prove shuffle 33 is used to prove that the shuffling center executed 
the algorithm shuffle correctly. The prove-shuffle algorithm involves a prover and 
a verifier. The prover is the shuffling center in this case. The verifier may be 
any entity, including a vote chooser. The probabilistic behavior of the algorithm 
will be determined by an output of a suitable hash function, but it may also be 
a random beacon. The algorithm comprises a permuted pair of (S{X l ),S{X 7 )) i 
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showing that they are indeed generated from inputs X { and X 2 as equations (2). 
Assume a random string has been committed using chameleon commitment to the 
vote chooser. 

prove shuffle 

1. The prover uniformly chooses d t d* and calculates 

W\) = (A x • gc' mod p 3 &2 ' V c ' mod p) 
E(X 2 ) = (B { - g c "mod p, B 2 - yc ;/ mo d p) 

post E(Xi),E(X 2 ) in the order according to the committed string. 

2a. With probability the prover is asked to reveal d and c". The verifier 
checks if E{X x ),E(Xi) is made consistently, 

2b. With probability 1, the prover is asked to reveal ti = c x - d and t 2 = c 2 ~d\ 
The verifier checks that E(X X ) and 2?(Jf 2 ) can indeed be generated from 
S(Xi) t S(Xi) using ti 9 h,9 aad y. 

The encrypted votes posted by the vote generating centers are successively pro- 
cessed by the shuflling centers 11(1), 11(2), . . ,ll(m) until the last center provides 
as its output a randomly, untraceably ordered set of encrypted votes for each vote 
chooser. 

The vote chooser 12(i) chooses its ballot using the secret messages from the vote 
generating center and shuffling centers through untappable secure channels 16 (i), 
17(l),17(2),...andl7(in). 

Invalidation of chameleon commitments of shuffling centers can be realized in 
a similar manner as invalidated commitments of vote generating center. 

Having described a preferred method of practicing the present invention, pre- 
ferred embodiments useful for practicing the invention will now be described. 

Figure 1 schematically illustrates a preferred embodiment for practicing the inven- 
tion. The vote generating center 10, vote choosers 12(1), 12(2), . . . 12(i) } mixing 
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centers 14(1), 14(2), . . .ll(n) and vote counting center 15 use personal computers 
or workstations connected to a conventional electronic bulletin board 13. There 
are untappable secure channels 16(1),16(2) . . . 16(£) so that the vote generating 
center can send a secret message to each vote chooser. All elements (senders, 
verifiers, centers and the like) comprising the message transfer process interact by 
posting messages to and receiving messages from the bulletin board 13, except 
when the vote generating center sends decommitting messages to vote choosers 
via untappable channel 16. The vote generating center or vote choosers or vote 
counting center can also serve as mixing centers or vote counting centers. The per- 
sonal computers either contain software to perform the method described above 
or alternatively contain in hardware or software embodiments of the elements de- 
scribed in Figure 2. 

Figure 2 illustrates how messages are transferred to achieve receipt-free voting. 
Fbr each vote chooser 12(i), vote generating center 10 generates encrypted votes 
using a vote constructor 26 as described above. The vote generating center then 
follows process prove 20 which comprises algorithms commitment 21, prove 1-0 22 
and decommitment 23. The output of decommitment is sent to vote chooser 12 (i) 
through untappable channel 16(i). Other outputs of the vote generating center 10 
is posted on the bulletin board 13. The vote chooser 12(i) follows the processes 
verification 24 and selection 25, and outputs selected votes from the encrypted 
votes on the bulletin board. The selected votes of all the vote choosers 12(1), 
12(2) -..12(£) are anonymously transferred to vote counter 15 through anony- 
mous channel 14. 

Figure 3 schematically illustrates a preferred embodiment for practicing the in- 
vention with a shuffle net. The vote generating center 10, vote shuffling centers 
11(1), 11(2), ...ll(m), vote choosers 12(1), 12(2), ...12#), mixing centers 14(1), 
14(2), . . .ll(n) and. vote counting center 15 use personal computers or workstations 
connected to a conventional electronic bulletin board 13. There are untappable 
channels 16(1) ,16(2) . . . 16(Q so that the vote generating center can send a secret 
message to each vote chooser. There are also untappable channels 17(1),17(2) 
...17(m) so that the shuffling centers 11(1), 11(2), ...ll(m) can send a secret 
message to vote chooser 12(i). All elements (senders, verifiers, centers and the 
like) comprising the message transfer process interact by posting messages to and 
receiving messages from the bulletin board, except for the vote generating center 
or shuffling centers which send decommitting messages to a vote chooser via un- 
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tappable channels. The vote generating center or vote choosers or vote counting 
center or shuffling centers can also serve as mixing centers or vote counting centers 
or shuffling centers. The personal computers either contain software to perform 
the method described above or alternatively contain in hardware or software em- 
bodiments the elements described in Figures 4 and 5. 

Figure 4 illustrates how messages are transferred to achieve receipt-free voting 
with a shuffle net. For each vote chooser 12 (i), vote generating center 10 gener- 
ates encrypted votes which are posted on the bulletin board 13. Then shuffling 
center 11(1) reads encrypted votes from the bulletin board 13 and follows pro- 
cesses shuffle 30 and prove 31, and output shuffled votes to the bulletin board 13, 
while sending a decommitting message to vote chooser 12 (i) through untappable 
channel 17(1). Similarly, the succeeding shuffling centers read the proceeding cen- 
ters output from bulletin board 13, and post its output to the bulletin board for 
the next shuffling center, while sending its decommitting message to vote chooser 
12(i) through untappable channel 17(1). The last shuffling center's output will 
be read by the vote chooser 12(i), which follows the processes verification 35 and 
selection 36, and outputs selected votes from the encrypted votes on the bulletin 
board. The selected votes of all the vote choosers 12(1), 12(2) . . . 12(^) are anony- 
mously transferred to vote counter 15 through anonymous channel 14. 

Figure 5 schematically illustrates a shuffling center ll(i). The shuffling center 
follows process shuffle 30 and process prove 31. Process prove 31 comprises algo- 
rithms commitment 32, prove shuffle 33 and decommitment 34. 

While there has been described and illustrated a preferred method and appa- 
ratus of secure receipt free electronic voting, it will be apparent to those skilled in 
the art that variations and modifications are possible without deviating from the 
broad teachings and spirit of the present invention which shall be limited solely 
by the scope of the claims appended hereto. 
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Figure 1 is a schematic illustration of a preferred embodiment for practicing the 
present invention; 

Figure 2 is a schematic illustration of message flow; 

Figure 3 is a schematic illustration of a preferred embodiment for practicing the 
present invention with shuffling centers; 

Figure 4 is a schematic illustration of a message flow with shuffling centers; and 
Figure 5 is a schematic illustration of a shuffling center. 
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SHUFFLING CENTER 11(i) 



SHUFFLE 30 



PROVE 31 

I COMMITMENT 32 
PROVE SHUFFLE 33 



DECOMMITMENT 34 



FIG 5 



L Abstract 

A number-theoretic based algorithm provides for secure receipt-free voting. A 
vote generating center generates a choice of votes for each voter or vote chooser. 
The votes are encrypted, shuffled, and conveyed to a vote chooser along with 
information regarding how the votes were shuffled without being intercepted en 
route. The information is preferably sent along untappable secure channels. The 
method can incorporate validification of generation and shuffling of the votes using 
chameleon commitment and interactive proofs. The invention can be realized by 
current-generation personal computers with untappable channels and access to an 
electronic bulletin board. 



2. Representative Drawing 
FIG 1 
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